GHSA-7gh2-8q93-87hp
Dashboard / Vulnerabilities / GHSA-7gh2-8q93-87hp
Summary: Wizkunde SAMLBase SAML Bypass
Details: Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-5387, https://github.com/GoGentoOSS/SAMLBase/issues/3, https://github.com/GoGentoOSS/SAMLBase/commit/482cdf8c090e0f1179073034ebcb609ac7c3f5b3, https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations, https://github.com/GoGentoOSS/SAMLBase, https://www.kb.cert.org/vuls/id/475445
Affected packages
Package
Name: gogentooss/samlbase
Purl: pkg:composer/gogentooss/samlbase
Affected ranges
Type: ECOSYSTEM
Events:
